Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2965-1 cacti security update
EUVD EUVD EUVD-2018-2143 Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T07:32:00.970Z

Reserved: 2018-04-12T00:00:00

Link: CVE-2018-10061

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-04-12T16:29:00.353

Modified: 2024-11-21T03:40:44.840

Link: CVE-2018-10061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses